Authorization Bypass in Pelican Panel by Pelican
CVE-2026-92762
8.7HIGH
What is CVE-2026-92762?
Pelican Panel versions prior to 1.0.0-beta35 have a security flaw where startup write permissions are incorrectly enforced through disabled form controls instead of robust server-side checks. This vulnerability allows attackers who have 'startup.read' permissions to execute Livewire state updates. By doing so, they can call afterStateUpdated callbacks to alter startup commands, docker images, and environment variables, which could lead to the execution of arbitrary commands within the container environment. This flaw poses significant risks to the system integrity and security.
Affected Version(s)
panel 0 < 1.0.0-beta35
